Privacy policy
This translation is provided for information only. The German version is legally binding; German law applies.
This policy applies to tiaki.de and the application app.tiaki.de. We process personal data only to the extent necessary for operation, security and the agreed services.
1. Controller
INREMA Unternehmensberatung GmbH, Rentmeister-Wilthelm-Weg 16, 33181 Bad Wünnenberg, Germany, represented by its managing director Tanja Rüdiger.
Email: hallo@tiaki.de
For any questions about data protection and to exercise your rights, you can reach us at hallo@tiaki.de.
2. Hosting
tiaki runs on servers of IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, in data centers in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with IONOS. The legal basis is Art. 6(1)(b) GDPR (provision of the service) and (f) GDPR (secure, stable operation).
3. Cloudflare (delivery and protection)
Traffic to tiaki.de and app.tiaki.de is routed through Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare protects against attacks, filters automated access and delivers content. In doing so, technical connection data such as IP address, time and browser information are processed. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a secure, available service. Cloudflare is certified under the EU-U.S. Data Privacy Framework; the EU Standard Contractual Clauses apply in addition.
Cloudflare Turnstile
On the sign-in and registration forms we use Cloudflare Turnstile to tell bots from humans. To do this, Turnstile evaluates technical characteristics of your browser and your connection; no advertising profiles are created. The legal basis is Art. 6(1)(f) GDPR (protection against abuse and account takeover).
4. Server logs
When you visit our pages, technically necessary data is processed (IP address, date and time, requested address, browser identifier). It is used for delivery, troubleshooting and fending off attacks (Art. 6(1)(f) GDPR) and is deleted after 14 days at the latest, unless it is needed to investigate a security incident.
5. Audience measurement on tiaki.de (Matomo)
On tiaki.de we use the Matomo software to measure how often our pages are visited, which pages are read and where visitors come from. This shows us which content is helpful. Matomo runs on a dedicated server of INREMA Unternehmensberatung GmbH in Germany (matomo.inrema.de); the data is not passed on to third parties.
We have configured Matomo without cookies, and it stores nothing on your device. Your IP address is truncated before it is stored, so it can no longer be attributed to you. Also processed are the date and time, the page visited, the previously visited page, and information about browser, operating system, device and screen size. The legal basis is our legitimate interest in an understandable, easily accessible website (Art. 6(1)(f) GDPR). You can object to the measurement at any time, for example with a short message to hallo@tiaki.de or by blocking scripts from matomo.inrema.de in your browser.
The measurement applies only to tiaki.de. We do not use any analytics tools in the application app.tiaki.de.
6. Registration and account
For an account, we process your name, your email address, your password (only as an irreversible hash using Argon2id) and the data of your two-factor sign-in (the secret encrypted, recovery codes only as an irreversible fingerprint). The legal basis is Art. 6(1)(b) GDPR. We store the account data for as long as your account exists; after that we delete it, unless statutory retention obligations prevent this.
To protect your account, we log sign-in attempts and security-relevant events with IP address and time (Art. 6(1)(f) GDPR). We delete sign-in attempts after 30 days and security logs after 12 months at the latest.
7. Cookies
app.tiaki.de sets only technically necessary cookies (Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG), which do not require consent:
- __Host-tiaki – keeps you signed in after you sign in (12 hours at most, invalid after 30 minutes of inactivity).
- __Host-tiaki-v – remembers your step while signing in or registering (30 minutes at most).
- __Host-tiaki-b – binds forms to your browser, protecting against forged requests (30 days).
We do not use any analytics or advertising trackers on app.tiaki.de.
8. Emails
We send you emails that are necessary for your account, for example to confirm your address or in the event of security-relevant events (Art. 6(1)(b) and (f) GDPR). They are sent via our own mail server. If you write to us, we process your message in order to answer it (Art. 6(1)(b) or (f) GDPR).
9. Connecting social networks and Google
In tiaki you can connect your business’s profiles to plan and publish posts, reply to comments and messages, and view statistics. You establish the connection yourself by signing in with the respective provider and allowing tiaki access. You can disconnect it at any time in tiaki under “Profiles” or revoke the permission directly with the provider. The legal basis is Art. 6(1)(b) GDPR (provision of the service you have chosen).
What tiaki processes: the access key (token) that the provider issues after your approval – stored only in encrypted form; name, identifier and profile picture of the connected profile or page; your published posts with metrics (reach, views, reactions, follower growth); comments, replies, mentions and direct messages addressed to your profile, including the name, identifier and profile picture of the person writing.
What for: solely to show you this content in tiaki, to publish your replies and posts on your behalf and to show you analytics for your own profile. We do not sell this data, do not use it for advertising and do not pass it on to third parties – except to the respective provider when you publish or reply to something.
How long: for as long as the profile is connected. If you disconnect it, we delete the access key immediately and the stored posts, metrics, comments and messages of that profile within 30 days.
Meta: Facebook, Instagram, Threads
The provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. tiaki uses Meta’s official interfaces (Facebook Login for Business, Instagram API, Threads API). You can connect Instagram via your Facebook Page or directly with your Instagram account. For messages, tiaki uses Meta’s Messenger and Instagram interfaces; Meta itself processes your data according to its own privacy policy (facebook.com/privacy/policy, help.instagram.com/519522125107875, help.instagram.com/515230437301944 for Threads). A transfer to Meta Platforms, Inc. in the USA is possible; Meta is certified under the EU-U.S. Data Privacy Framework.
Google Business Profile
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. tiaki uses the Business Profile APIs to manage posts, opening hours, reviews and replies of your Business Profile. The use of data received from Google complies with the Google API Services User Data Policy, including the Limited Use requirements. Google is certified under the EU-U.S. Data Privacy Framework.
Data deletion
How to delete the data tiaki has received from a network:
- In tiaki, go to Profiles and tap Disconnect next to the network – access is deleted immediately, all content of the profile within 30 days.
- Or remove the permission with the provider (Facebook: Settings → Apps and Websites; Instagram: Settings → Apps and Websites; Threads: Settings → Account → Website permissions; Google: myaccount.google.com/permissions). Meta notifies us of this automatically; we then delete as described under 1., and you receive a confirmation code whose status you can check at app.tiaki.de/datenloeschung/status.
- Or send a short message to hallo@tiaki.de – we delete within 30 days and confirm this to you.
You can delete your entire tiaki account yourself under Settings → Account → “Delete account” (with two-factor confirmation) or by sending a message to hallo@tiaki.de. We retain invoices for ten years in accordance with Section 147 of the German Fiscal Code (AO); everything else is deleted.
10. AI features (OpenAI)
When you have tiaki’s AI create or revise texts or images, we send your input (e.g. keywords, draft, details from your briefing) to OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland. Under the contract, OpenAI does not use this data to train its models and deletes it after 30 days at the latest. A data processing agreement is in place with OpenAI; any transfer to the USA is safeguarded by the EU Standard Contractual Clauses. The legal basis is Art. 6(1)(b) GDPR. Please do not enter sensitive data of third parties in AI inputs.
11. Files and images (Cloudflare R2)
Images, videos and files that you upload to tiaki are stored encrypted in the R2 storage service of Cloudflare, Inc. (address see Section 3), storage location EU. They are retrieved only through tiaki itself. We delete them when you delete them or when your account ends (according to the deadlines of your plan). The legal basis is Art. 6(1)(b) GDPR.
12. Payment and invoices (Stripe, Lexware)
If you book a plan, Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland, processes your payment data; tiaki itself never sees full card or account numbers. We create invoices with Lexware Office by Haufe Service Center GmbH, Munzinger Straße 9, 79111 Freiburg, Germany. Processed are company name, address, email address, VAT ID and the services booked. The legal basis is Art. 6(1)(b) and (c) GDPR; we retain invoices for 10 years (Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB)).
13. Link checking (Google Safe Browsing)
To make sure your short links, bio pages and landing pages don’t lead to dangerous sites, tiaki checks the destination addresses with Google Safe Browsing (Google Ireland Limited). Only the destination address is transmitted, no data about you or your visitors. The legal basis is Art. 6(1)(f) GDPR (protection against malicious sites).
14. Notifications on your device (web push)
If you allow notifications, tiaki stores the address your browser provides for this and sends alerts (e.g. new message, post published) via the push service of your browser vendor (Google, Apple, Mozilla or Microsoft). The content is encrypted. You can turn off notifications in tiaki or in your browser at any time. The legal basis is your consent (Art. 6(1)(a) GDPR).
15. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). To do so, write to us at hallo@tiaki.de.
You can also lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
16. No automated decisions
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you.
Last updated: Sept 30, 2026